Agreement

Data processing agreement (DPA)

Last updated: 11 September 2026

This data processing agreement (the “Agreement”) governs Exeqo AB’s processing of personal data when Exeqo acts as a processor for the customer in connection with delivering the Exeqo service (also known as Ngager).

The Agreement is an annex to the customer’s order, subscription agreement or terms of use with Exeqo AB and applies automatically when the customer enters into or uses the service, unless the parties agree otherwise in writing.

The Agreement is intended to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR).

1. Parties

Controller (the “Customer”): the legal entity that contracts for the service and that determines the purposes and means of processing personal data in the platform.

Processor (“Exeqo” / the “Processor”):

Exeqo AB

Organisation number: 559372-8297

Södra Allégatan 3

413 01 Gothenburg, Sweden

Privacy questions: privacy@exeqo.se

Security incidents: security@exeqo.se

2. Roles and scope

The Customer is the controller of personal data processed in the service on the Customer’s behalf. Exeqo is the processor and processes such data only according to the Customer’s documented instructions and this Agreement.

The Agreement does not cover processing where Exeqo itself is the controller (for example customer relationships, billing, support cases with Exeqo, sales or the website). That processing is described in Exeqo’s privacy policy.

3. Subject matter of the processing

Purpose

To provide, operate, maintain and support the Exeqo cloud service according to the Customer’s agreement and instructions — for example communication, information, onboarding, checklists, learning and other internal processes the Customer enables.

Categories of data subjects

  • The Customer’s employees and other staff,
  • administrators and managers at the Customer,
  • consultants, hourly staff and other external persons the Customer grants access,
  • other users the Customer chooses to invite.

The service is not intended for processing the Customer’s end customers or guests as a separate category.

Categories of personal data

  • Identity and contact details (name, email, phone — normally required for user accounts),
  • organisation details (role, department, workplace — optional),
  • profile photo (optional),
  • content users create or upload (for example messages, checklists, learning status and documents),
  • technical operational information and logs that may occur for security and troubleshooting (Exeqo does not intentionally store IP addresses as a separate purpose; Application Insights telemetry is normally retained for about 30 days).

Exeqo does not process special categories of personal data (sensitive data) as an intentional purpose of the service. The Customer may upload documents and other content; the Customer is responsible for the lawfulness of that content and for the legal basis towards data subjects.

4. Instructions

Exeqo may process personal data only according to this Agreement, the Customer’s service agreement and the Customer’s other written instructions. If Exeqo considers an instruction to conflict with the GDPR or other applicable law, Exeqo shall notify the Customer without undue delay.

Processing required by law to which Exeqo is subject is permitted. Exeqo shall then, if legally possible, inform the Customer before the processing takes place.

5. Confidentiality

Exeqo ensures that persons authorised to access personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to what is needed to deliver the service.

6. Security

Exeqo implements appropriate technical and organisational measures taking into account risk, the state of the art and cost, including:

  • encryption in transit (TLS) and protection of data at rest according to provider standards,
  • access control and authentication (including via AWS Cognito),
  • environment separation and limited internal access on a need-to-know basis,
  • logging and monitoring for operations and incident handling,
  • backup and recovery routines within the cloud platform.

Primary application data and files are stored in Microsoft Azure, region Sweden Central. User authentication uses AWS Cognito in region eu-north-1.

7. Sub-processors

The Customer grants Exeqo a general authorisation to engage sub-processors to deliver the service. Exeqo shall enter into written agreements with sub-processors that impose data-protection obligations equivalent to those in this Agreement.

Exeqo will inform the Customer of planned additions or replacements of sub-processors in good time so the Customer may object on reasonable data-protection grounds. If the Customer objects and the parties cannot agree, the Customer may terminate the service according to the applicable terms.

Current sub-processors (overview)

  • Microsoft Azure — hosting, compute, networking, databases (PostgreSQL) and storage — Sweden Central / EU,
  • Microsoft Application Insights — operational telemetry and troubleshooting — tied to the Azure environment,
  • Amazon Web Services (AWS Cognito) — authentication and user accounts — eu-north-1,
  • Twilio SendGrid — transactional email,
  • OneSignal — push notifications,
  • Sendbird — in-app chat.

Development tools such as GitHub are used for source code and CI and do not normally process the Customer’s personal data in production; they are therefore not listed here.

An updated list may be requested via privacy@exeqo.se.

8. Transfers outside the EU/EEA

Some processing via sub-processors may involve personal data being transferred to or made available from countries outside the EU/EEA (for example with global cloud and messaging services).

Where such a transfer occurs, it shall have a lawful basis under the GDPR, for example an adequacy decision or the European Commission’s standard contractual clauses (SCCs), together with any supplementary measures required.

9. Data subject rights

Exeqo shall assist the Customer, to the extent possible given the nature of the processing, so the Customer can respond to data subject requests under the GDPR. Requests received directly by Exeqo from a data subject belonging to the Customer are referred primarily to the Customer, unless otherwise required.

10. Personal data breaches

Exeqo shall without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer’s personal data, notify the Customer.

The notice shall include the information Exeqo reasonably has available so the Customer can meet its GDPR obligations (including the nature of the breach, categories and approximate number of data subjects concerned, likely consequences, and measures taken or proposed).

Incidents are reported to security@exeqo.se. The Customer shall provide a current incident contact address in its account or agreement.

11. Assistance, audits and information

Exeqo shall, taking into account the nature of the processing and the information available to Exeqo, assist the Customer with information needed for data protection impact assessments and prior consultation with a supervisory authority when relevant.

Exeqo shall make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR. The Customer may, with reasonable notice and during business hours, carry out an audit or appoint an independent auditor, without disrupting operations or other customers’ security. The parties shall primarily rely on available audit reports, certificates or written answers.

12. Deletion and return

When the service agreement ends, the Customer shall for 30 days have the opportunity to export its data in a commonly used format, to the extent the function exists in the service or as agreed with support@exeqo.se.

Thereafter Exeqo shall within 30 days delete or anonymise personal data processed as a processor, unless law requires longer retention or the parties agree otherwise in writing.

13. Liability

Liability for breach of this Agreement follows the liability and limitations in the parties’ main agreement or terms of use, unless mandatory law provides otherwise.

14. Term and changes

The Agreement applies for as long as Exeqo processes personal data on behalf of the Customer under the service agreement.

Exeqo may update this Agreement. Material changes will be notified to the Customer within a reasonable time before they take effect, by email or in the service. If the Customer does not accept the change, the Customer may terminate the service according to the applicable terms.

15. Governing law

This Agreement shall be construed in accordance with Swedish law and the GDPR. Disputes relating to the Agreement are handled under the same forum as in the parties’ main agreement or terms of use.

16. Contact

  • Privacy and DPA: privacy@exeqo.se
  • Security incidents: security@exeqo.se
  • Product support: support@exeqo.se
  • General enquiries: hello@exeqo.se